VDB
Sign up
CRITICAL9.8

GHSA-3fhf-6939-qg8p

rest-client Gem Vulnerable to Session Fixation

Quick fix

GHSA-3fhf-6939-qg8p — rest-client: upgrade to the fixed version with the command below.

bundle update rest-client

Details

REST client for Ruby (aka rest-client) versions 1.6.1.a until 1.8.0 allow remote attackers to conduct session fixation attacks or obtain sensitive cookie information by leveraging passage of cookies set in a response to a redirect.

Are you affected?

Enter the version of the package you're using.

Affected packages

RubyGems/rest-client
Introduced in: 1.6.1.aFixed in: 1.8.0
Fixbundle update rest-client

References